Improper Certificate Validation in wolfSSL - CVE-2026-93302
Published: October 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass peer authentication.
The vulnerability exists due to improper certificate validation in the trusted peer certificate verification path when processing a peer certificate. A remote attacker can present a forged certificate that reuses trusted certificate identity fields to bypass peer authentication.
Exploitation requires knowledge of the CA certificates loaded as trusted peer certificates.